• Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login
Netgate Discussion Forum
  • Categories
  • Recent
  • Tags
  • Popular
  • Users
  • Search
  • Register
  • Login

Default deny rule IPv4 (1000000103)

2.4 Development Snapshots
5
9
36.2k
Loading More Posts
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • Y
    yon
    last edited by Aug 9, 2017, 9:36 AM

    why it has this rule ? how i edit it?

    Default deny rule IPv4 (1000000103)
    Default deny rule IPv6 (1000000105)
    ![Screenshot- Status- System Logs- Firewall- Normal View.jpg](/public/imported_attachments/1/Screenshot- Status- System Logs- Firewall- Normal View.jpg)
    ![Screenshot- Status- System Logs- Firewall- Normal View.jpg_thumb](/public/imported_attachments/1/Screenshot- Status- System Logs- Firewall- Normal View.jpg_thumb)

    If you are interested in free peering for clearnet and dn42,contact me !

    1 Reply Last reply Reply Quote 0
    • K
      kpa
      last edited by Aug 9, 2017, 10:33 AM

      That's the most basic design building block for a firewall, it sets the default policy for the rules to "deny all by default". You can't edit it and that's on purpose.

      1 Reply Last reply Reply Quote 0
      • J
        johnpoz LAYER 8 Global Moderator
        last edited by Aug 9, 2017, 12:49 PM

        Yeah your not going to want to ever disable the default deny.

        You have a couple of options to reduce log spam… You can turn off logging of the default rules, you could create a rule that is same as default deny but do not log it, etc.

        I for example do not like the out of state log entries that the default rule logs - I see many of those in your log.  So I turn off logging of the default rule, and then just have a block rule at the bottom that logs only SYN traffic.

        An intelligent man is sometimes forced to be drunk to spend time with his fools
        If you get confused: Listen to the Music Play
        Please don't Chat/PM me for help, unless mod related
        SG-4860 24.11 | Lab VMs 2.7.2, 24.11

        1 Reply Last reply Reply Quote 0
        • K
          kpa
          last edited by Aug 9, 2017, 1:11 PM

          Turning off logging for the default deny is probably the best option, it is only there to draw your attention to what gets logged and if you don't want to see it. Specifically logging only what you want to see is the way to go.

          1 Reply Last reply Reply Quote 0
          • Y
            yon
            last edited by Aug 10, 2017, 8:32 AM

            why blocck these ip ?  i dont understand.

            If you are interested in free peering for clearnet and dn42,contact me !

            1 Reply Last reply Reply Quote 0
            • K
              kpa
              last edited by Aug 10, 2017, 8:44 AM

              https://doc.pfsense.org/index.php/Why_do_my_logs_show_%22blocked%22_for_traffic_from_a_legitimate_connection

              1 Reply Last reply Reply Quote 0
              • B
                bimmerdriver
                last edited by Aug 10, 2017, 4:23 PM

                It would really be nice if it were possible to put rules ahead of the default deny rule. I would use this to block unwanted messages without logging so they don't clutter the log (e.g., IGMP).

                1 Reply Last reply Reply Quote 0
                • G
                  GruensFroeschli
                  last edited by Aug 10, 2017, 4:36 PM

                  @bimmerdriver:

                  It would really be nice if it were possible to put rules ahead of the default deny rule. I would use this to block unwanted messages without logging so they don't clutter the log (e.g., IGMP).

                  Not sure what you mean, but every rule you define is ahead of the default deny rule.

                  We do what we must, because we can.

                  Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                  1 Reply Last reply Reply Quote 0
                  • J
                    johnpoz LAYER 8 Global Moderator
                    last edited by Aug 10, 2017, 5:28 PM

                    ^ exactly.. Which is why I stated you could just create a rule - and not log, and so did kpa.

                    If you the rules you created were below the default deny, then the rules you create would never been used..  Since traffic would be denied before it got to the rule ;)

                    An intelligent man is sometimes forced to be drunk to spend time with his fools
                    If you get confused: Listen to the Music Play
                    Please don't Chat/PM me for help, unless mod related
                    SG-4860 24.11 | Lab VMs 2.7.2, 24.11

                    1 Reply Last reply Reply Quote 0
                    3 out of 9
                    • First post
                      3/9
                      Last post
                    Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.